Secure Endpoint and ClamAV

CVE-2024-20506: ClamAV Privilege Handling Escalation Vulnerability

A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an authenticated, local attacker to corrupt critical system files.

Published

ExploitedNot in CISA KEV
Ransomware useNot reportedPer CISA
SeverityMEDIUMCVSS 3.1 6.1
EPSS0.32%Chance of exploitation in 30 days
Public exploitNot tracked
FixNot yet

Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.

Affected and fixed versions

Product / branchFixed in
ClamAV 1.4See the advisory
ClamAV 1.3See the advisory
ClamAV 1.0See the advisory
ClamAV 1.0See the advisory
ClamAV 1.0See the advisory
ClamAV 1.0See the advisory
ClamAV 1.0See the advisory
ClamAV 1.0See the advisory
ClamAV 1.0See the advisory
ClamAV 1.2See the advisory
ClamAV 0.105See the advisory
ClamAV 0.104See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an authenticated, local attacker to corrupt critical system files.

The vulnerability is due to allowing the ClamD process to write to its log file while privileged without checking if the logfile has been replaced with a symbolic link. An attacker could exploit this vulnerability if they replace the ClamD log file with a symlink to a critical system file and then find a way to restart the ClamD process. An exploit could allow the attacker to corrupt a critical system file by appending ClamD log messages after restart.

Sources

KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.